CVE Vulnerabilities

CVE-2008-5913

Published: Jan 20, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
3.6 LOW
AV:N/AC:H/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a temporary footprint and an in-session phishing attack.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.5 (including)3.5 (including)
FirefoxMozilla3.5.1 (including)3.5.1 (including)
FirefoxMozilla3.5.2 (including)3.5.2 (including)
FirefoxMozilla3.5.3 (including)3.5.3 (including)
FirefoxMozilla3.5.4 (including)3.5.4 (including)
FirefoxMozilla3.5.5 (including)3.5.5 (including)
FirefoxMozilla3.5.6 (including)3.5.6 (including)
FirefoxMozilla3.5.7 (including)3.5.7 (including)
FirefoxMozilla3.5.8 (including)3.5.8 (including)
FirefoxMozilla3.5.9 (including)3.5.9 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:3.6.4-8.el4*
Red Hat Enterprise Linux 5RedHatdevhelp-0:0.12-21.el5*
Red Hat Enterprise Linux 5RedHatesc-0:1.1.0-12.el5*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.6.4-8.el5*
Red Hat Enterprise Linux 5RedHatgnome-python2-extras-0:2.14.2-7.el5*
Red Hat Enterprise Linux 5RedHattotem-0:2.16.7-7.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.2.4-10.el5*
Red Hat Enterprise Linux 5RedHatyelp-0:2.16.0-26.el5*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntuhardy*
FirefoxUbuntulucid*
FirefoxUbuntuupstream*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*
Xulrunner-1.9.1Ubuntuupstream*
Xulrunner-1.9.2Ubuntudevel*
Xulrunner-1.9.2Ubuntuhardy*
Xulrunner-1.9.2Ubuntujaunty*
Xulrunner-1.9.2Ubuntukarmic*
Xulrunner-1.9.2Ubuntulucid*
Xulrunner-1.9.2Ubuntuupstream*

References